Created on
12-19-2022
08:19 AM
Edited on
10-13-2025
11:04 PM
By
Jean-Philippe_P
Description
This article describes how to disable bypassing the FortiAuthenticator Agent login on a Windows machine.
Scope
FortiAuthenticator 6.4.6, FortiAuthenticator Agent 4.2.
Solution
Since it is possible to log in to a Windows machine without OTP and bypass the FortiAuthenticator Agent, it is recommended to disable 'Permit Built-in Password Providers' under the FortiAuthenticator Agent settings.
Navigate to Credential Provider Options -> Permit Built-in Password Providers.
Disable the setting and select Apply.
This setting must be configured manually on each PC.
Lock the Windows machine and log in again, this time using the FortiAuthenticator Agent login window.
Related documents:
Introduction: FortiAuthenticator Agent for Microsoft Windows 4.2 Install Guide
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.